Privacy Policy
Privacy Policy
and Personal Data Protection
“Sally” application and website — Effective date: 08/09/2026
This Policy explains what personal data we collect when you use the “Sally” application and website, for what purposes, on what legal basis, with whom we share it, for how long we retain it, and what rights you have. It replaces and supersedes any previous version.
1. Data Controller
| Name | COINBUX S.A. |
|---|---|
| Registered seat | 309 El. Venizelou Ave., Kallithea, Greece |
| GEMI No. | 172545503000 |
| Tax ID (VAT) | 802228090 |
| info@meet-sally.com | |
| Website | https://www.meet-sally.com |
The above company is hereinafter referred to as “the Company” or “we” and acts as Data Controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (hereinafter “GDPR”).
2. Data Protection Officer
The Company has appointed a Data Protection Officer in accordance with Articles 37 to 39 GDPR. You may contact them directly for any matter relating to the processing of your data and the exercise of your rights.
| Name | Georgios Stouraitis |
|---|---|
| Capacity | Lawyer, member of the Athens Bar Association, Reg. No. 25996 |
| info@meet-sally.com | |
| Postal address | 10 Kifisias Ave., P.C. 115 26, Athens |
Communication with the Data Protection Officer is free of charge and confidential, in accordance with Article 38(5) GDPR.
3. Scope of Application
3.1. This Policy applies to data collected by the Company through:
- the website www.meet-sally.com,
- the “Sally” mobile application, on iOS and Android operating systems,
- any electronic communication with us.
3.2. What this Policy does NOT cover. This Policy does not cover:
- the processing of your data by the partner credit institution “TBI BANK EAD, Branch Greece” after submission of a loan application. From that point onward, its own privacy notice applies,
- the processing carried out by ITBS Finance SMPC (“finker”) as a licensed Account Information Service Provider, in respect of which it acts as an independent controller,
- the processing carried out by app stores (App Store, Google Play) when downloading the Application,
- third-party websites you may reach via links.
4. Categories of Data Subjects
This Policy concerns two categories of persons: visitors to the website, who have not created an account, and registered Users of the Application. Where a provision concerns only one category, this is expressly stated.
5. Categories of Data We Collect
5.1. Registration and account data. Full name, email address, mobile phone number, account identifier, identification details via a Google or Apple account if you choose that sign-in method, preference settings, history of acceptance of the legal texts.
5.2. Bank account data. Number and name of the connected account, balances, account transactions with a history of up to twenty-four (24) months, names of counterparties and merchants, amounts, dates, transaction categorization, recurring charges. Passwords, PINs or security codes are not collected and are never made known to us.
5.3. Content of conversations with the Digital Assistant. The messages you send to the Digital Assistant and the responses you receive, as well as the transaction data used to formulate the response.
5.4. Technical and usage data. IP address, device identifiers, device type, operating system, application version, push notification identifiers, connection log files, in-app usage events, crash and error reports.
5.5. Communication and support data. The content of your messages to support and our responses. Support is provided exclusively in writing. Support phone calls are not made or recorded.
5.6. Loan application data. Application number, full name, email address, mobile phone number, transaction-behaviour information and solvency data transmitted to the Bank following your consent, as well as the application number and loan amount we receive as confirmation from the Bank.
5.7. Special category data. The Company does not request or seek to collect special category data under Article 9 GDPR. However, transactions on a bank account may indirectly reveal such information, for example through a merchant's trade name. The Company does not extract, infer or use such information and does not build profiles based on it. Specifically for the Game in Section 11, a closed list of permitted spending categories is applied, so that such transactions are technically excluded. For the other features, the corresponding technical measure is under development and will be implemented by 31/12/2028.
5.8. Game participation data. Participation identifier, the date of birth you declare on entry, your answers, response time per question, your score and ranking, participation history per cycle, as well as spending totals per permitted category, used exclusively to calculate the correct answer. A history of any objections you submit is also kept.
5.9. Winners' data. Full name, contact details, the document shown to verify age before the prize is awarded, proof of the prize award, and, where the value of the prize gives rise to a tax obligation, the details required to submit the relevant declaration.
5.10. Subscription data. Subscription status, start, renewal and end dates, billing history as received from the payment provider or the app store, and the receipts issued. We do not receive or store full payment card details.
6. Source of the Data
The data originates: (a) from you, when you enter it in the Application or communicate with us, (b) from the automatic operation of the Application and the website, (c) from the bank where you hold your account, through the licensed Account Information Service Provider, following your consent, and (d) from the Bank, as regards confirmation of the loan application.
7. Purposes and Legal Bases
| Purpose | Data categories | Legal basis |
|---|---|---|
| Creating and managing your account, providing the core features | 5.1 | Performance of a contract, Art. 6(1)(b) GDPR |
| Connecting bank accounts and retrieving balance/transaction information | 5.2 | Consent, Art. 6(1)(a) GDPR, in conjunction with Art. 67(2) of Law 4537/2018 |
| Transaction categorization, budgeting, expense overview | 5.2 | Performance of a contract, Art. 6(1)(b) GDPR |
| Operation of the AI Digital Assistant | 5.2, 5.3 | Performance of a contract, Art. 6(1)(b) GDPR |
| Transmission of data to the Bank for submitting a loan application | 5.6 | Consent, Art. 6(1)(a) GDPR |
| Operation of the Game, scoring, ranking and determination of winners | 5.8 | Performance of a contract, Art. 6(1)(b) GDPR, based on the Terms of Participation |
| Calculating the correct answer to questions based on your connected-account data | 5.2, 5.8 | Performance of a contract, Art. 6(1)(b) GDPR. Your entry into the Game constitutes the express request under Art. 67(2) of Law 4537/2018 |
| Verifying the age and identity of the winner and awarding the prize | 5.9 | Performance of a contract, Art. 6(1)(b) GDPR |
| Filing a declaration and paying tax on the prize, where due | 5.9 | Legal obligation, Art. 6(1)(c) GDPR, Arts. 91 and 92 of Law 2961/2001 |
| Prevention and handling of abusive or multiple participation in the Game | 5.1, 5.4, 5.8 | Legitimate interest, Art. 6(1)(f) GDPR |
| Management of the subscription, billing and issuing receipts | 5.10 | Performance of a contract, Art. 6(1)(b) GDPR |
| System security, fraud prevention and detection, integrity of the Service | 5.1, 5.4 | Legitimate interest, Art. 6(1)(f) GDPR |
| Technical support, error correction, stability of the Application | 5.4, 5.5 | Legitimate interest, Art. 6(1)(f) GDPR |
| Statistical analysis of use and improvement of the Service | 5.4 | Consent, Art. 6(1)(a) GDPR, see Cookie Policy |
| Commercial communication and newsletters | 5.1 | Consent, Art. 6(1)(a) GDPR and Art. 11 of Law 3471/2006 |
| Compliance with legal obligations, in particular tax and accounting | as applicable | Legal obligation, Art. 6(1)(c) GDPR |
| Establishment, exercise and defence of legal claims | as applicable | Legitimate interest, Art. 6(1)(f) GDPR |
Where processing is based on your consent, that consent is given through a separate, active choice and is freely revocable at any time, without affecting the lawfulness of processing carried out before the revocation.
8. The Digital Assistant and the Use of Artificial Intelligence
8.1. The “Sally” Digital Assistant is an artificial intelligence system, which the Company places on the market and puts into service under its own name, and is therefore considered a provider under Article 3(3) of Regulation (EU) 2024/1689. You are expressly informed at the start of each conversation that you are interacting with an artificial intelligence system, in accordance with Article 50(1) of the same Regulation.
8.2. To formulate responses, the content of the conversation and related transaction data are transmitted via an application programming interface to the artificial intelligence model provider OpenAI, which acts as processor on our behalf under an Article 28 GDPR agreement.
8.3. Processing by the above provider takes place in the United States of America. Where processing takes place outside the European Economic Area, the safeguards of Section 13 apply.
8.4. Your data is not used to train, further fine-tune or improve the provider's artificial intelligence models, based on an express contractual commitment.
8.5. The Digital Assistant does not make or prepare decisions that produce legal effects or significantly affect you. It is not used to assess your creditworthiness.
9. Connecting Bank Accounts and the Role of the Parties
9.1. Retrieval of your bank account information is carried out by ITBS Finance SMPC (“finker”), a licensed Account Information Service Provider under Directive (EU) 2015/2366 and Law 4537/2018.
9.2. Your consent is given within the secure strong customer authentication environment of your bank. With respect to this service, ITBS Finance SMPC acts as an independent controller towards you.
9.3. The Company receives the data as a third-party recipient, based on your consent. It processes it exclusively for the purposes described in Section 7. The data is not used for purposes other than those of the service you expressly requested. The licensed provider is correspondingly bound by Article 67(2) of Law 4537/2018.
9.4. You may revoke your consent at any time, free of charge, through the Application or through your bank.
10. Transfer of Data to the Bank for a Loan Application
10.1. If you choose to submit an application for the loan product presented through the Application, certain of your data is transmitted to “TBI BANK EAD, Branch Greece” (196 Kifisias Ave., Chalandri, Attica, P.C. 152 31, GEMI No. 163671460001, Tax ID 996646764).
10.2. Role of the parties. The Company and the Bank act as independent controllers. Each independently determines the purposes and means of the processing it carries out and is independently liable towards you. There is no joint-controller relationship under Article 26 GDPR.
10.3. The following data is transmitted:
| Direction | Data | Legal basis |
|---|---|---|
| From the Company to the Bank | Application number, full name, email address, mobile phone number, transaction-behaviour information and solvency data | Consent, Art. 6(1)(a) GDPR |
| From the Bank to the Company | Confirmation of receipt of the application, application number, loan amount | Legitimate interest, Art. 6(1)(f) GDPR, for monitoring the proper functioning of the service |
10.4. The transfer takes place only after your separate, express and documented consent, given on a dedicated screen before submission of the application. Your refusal does not affect your use of the Application's other features.
10.5. After submission of the application, the Bank's processing of your data, including identification, assessment of your creditworthiness and any search of financial-behaviour data files, is governed by its own privacy notice. The Bank's Data Protection Officer can be reached at dpo@tbibank.gr.
11. The Knowledge Game and the Use of Your Data
11.1. What it is. Within the Application, an optional prize game is available to subscribers, consisting of questions about your own finances. The questions are common to all participants. For some of them, the correct answer results from the data of your own connected account, so that the game has an educational character.
11.2. Legal basis. The use of your connected-account data is itself the content of the Game and not a secondary use. Your entry into the Game, with express and active acceptance of the Terms of Participation and after being informed of the spending categories, constitutes the express request under Article 67(2) of Law 4537/2018. The legal basis is performance of the contract, Article 6(1)(b) GDPR. Processing stops when you exit the Game.
11.3. Closed list of categories. A question may arise only from the following spending categories: dining and food delivery, coffee and beverages, supermarket and household consumables, fuel and travel, entertainment subscription services, clothing and footwear. No other category is used. Transactions that could reveal special category data under Article 9 GDPR are expressly excluded, in particular transactions with pharmacies, doctors, hospitals, diagnostic centres, religious organizations, political parties and trade unions.
11.4. No artificial intelligence is used. The text of each question is predetermined and common. The amount constituting the correct answer is calculated by the Company's systems. For the purpose of the Game, no data is transmitted to an artificial intelligence model provider.
11.5. Exit. You may leave the Game at any time, free of charge, through the Application. Leaving immediately stops any use of your data for this purpose, without affecting your Subscription or your other use of the Application.
11.6. Complete separation from creditworthiness assessment. Your participation, answers, score and ranking are not used, directly or indirectly, as a criterion for assessing your creditworthiness, are not transmitted to the Bank, and do not affect your ability to obtain, or the terms of, any financing product. This separation is also ensured through technical measures.
11.7. Accuracy and objection. The correct answer results from the categorization of your transactions as performed by the Application. If you consider the categorization to be incorrect, you may submit an objection in accordance with the Terms of Participation and exercise the right of rectification under Article 16 GDPR.
11.8. Winners' details. Before a prize is awarded, the winner's age and identity are verified. The related document is retained only for as long as necessary and in any case for no more than thirty (30) days from the award of the prize.
12. Recipients and Processors
Your data is disclosed exclusively to the following recipients, to the extent necessary:
| Recipient | Role | Purpose | Country of processing |
|---|---|---|---|
| ITBS Finance SMPC (“finker”) | Independent controller, licensed AISP | Retrieval of account information | Greece |
| TBI BANK EAD, Branch Greece | Independent controller | Submission and assessment of loan application | Greece, Bulgaria |
| OpenAI | Processor | Operation of the Digital Assistant | USA |
| MongoDB | Processor | Storage of Application data | Sweden |
| Google Firebase | Processor | Application infrastructure and push notifications | Greece |
| PostHog | Processor | Statistical analysis of use, based on consent | Greece |
| Sentry | Processor | Error and crash detection and correction | Greece |
| Google Sign-In | Independent controllers | Sign-in to the Application with a third-party account, if you choose it | Greece |
| Stripe | Independent controller | Collection of the subscription fee and receipt issuance | Ireland |
| Lawyers, accountants, auditors | Independent controllers | Legal, accounting and audit support, as applicable | Greece |
| Competent public and judicial authorities | Independent controllers | Compliance with legal obligations | Greece |
A data processing agreement under Article 28 GDPR has been concluded with every processor.
We do not sell or rent your data to third parties, nor do we make it available for third-party advertising purposes.
13. Transfers Outside the European Economic Area
13.1. Some of the above providers may process data outside the European Economic Area, in particular in the United States.
13.2. Any such transfer takes place only if at least one of the following conditions is met:
- (a) an adequacy decision of the European Commission exists under Article 45 GDPR,
- (b) the Standard Contractual Clauses of European Commission Implementing Decision (EU) 2021/914 have been concluded, accompanied by a transfer impact assessment and any required supplementary measures,
- (c) another appropriate safeguard under Chapter V GDPR applies.
13.3. You may request a copy of the appropriate safeguards at info@meet-sally.com.
14. Automated Decision-Making
14.1. The Company does not make decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you, within the meaning of Article 22 GDPR.
14.2. Automatic categorization of your transactions and suggestions for organizing your finances are informational in nature and do not produce such effects.
14.3. Assessment of creditworthiness is carried out exclusively by the Bank, after submission of your application. Your rights towards the Bank regarding this assessment are described in its own notice.
14.4. Your participation and performance in the Game of Section 11 do not constitute and do not feed into a creditworthiness assessment criterion, whether by the Company or by the Bank.
15. Retention Periods
| Data category | Retention period | Criterion |
|---|---|---|
| User account data | For as long as the account is active and for five (5) years from its deletion | Art. 5(1)(e) GDPR, in conjunction with the five-year limitation period for tort claims, Art. 937 Greek Civil Code |
| Bank account and transaction data | For as long as consent is in effect and up to 15 days after its revocation or account deletion | Consent and the storage limitation principle |
| Content of conversations with the Digital Assistant | 12 months from the last interaction | Storage limitation principle, Art. 5(1)(e) GDPR |
| Loan application data held by the Company | Five (5) years from submission of the application | Limitation of claims and proof of consent |
| Game participation data, scores and rankings | Twelve (12) months from the end of the cycle they relate to | Proof of correctness of ranking and handling of objections |
| Winners' details and proof of prize awards | Five (5) years from the award | Limitation of claims and tax documentation |
| Age and identity verification document of the winner | Up to thirty (30) days from the award of the prize | Minimization principle, Art. 5(1)(c) GDPR |
| Subscription data and related receipts | Five (5) years from the end of the relevant tax year | Art. 13(2) of Law 5104/2024 |
| Technical log files and security data | Twelve (12) months | Legitimate security interest |
| Support requests with no pending matter | Twelve (12) months from their completion | Legitimate interest |
| Receipts and accounting records | Five (5) years from the end of the tax year | Art. 13(2) of Law 5104/2024 |
| Proof of consent, including acceptance of the legal texts | Five (5) years from its revocation or expiry | Accountability, Art. 5(2) and Art. 7(1) GDPR |
| Marketing communication data | Until consent is revoked | Consent |
After the above periods elapse, data is deleted or anonymized in a secure manner. Where data is retained in backup copies, it is deleted at the next backup-replacement cycle.
16. Security of Data
We apply appropriate technical and organizational measures in accordance with Article 32 GDPR, indicatively: encryption in transit, role-based access control under the necessity principle, two-factor authentication for User sign-in, maintenance of log files, separation of development and production environments, backup policies, staff confidentiality undertakings and regular training.
17. Breach Incidents
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in accordance with Article 33 GDPR. Where a breach is likely to result in a high risk, we notify you directly as well, in accordance with Article 34 GDPR.
18. Your Rights
You have, free of charge, the following rights:
- Right of access, Art. 15 GDPR.
- Right to rectification, Art. 16 GDPR.
- Right to erasure, Art. 17 GDPR, provided this does not conflict with an overriding retention obligation.
- Right to restriction of processing, Art. 18 GDPR.
- Right to data portability, Art. 20 GDPR.
- Right to object, Art. 21 GDPR, in particular to processing based on legitimate interest and to any processing for direct marketing purposes.
- Right not to be subject to a decision based solely on automated processing, Art. 22 GDPR, see Section 14.
- Right to withdraw consent, Art. 7(3) GDPR, without affecting the lawfulness of prior processing.
Rights are exercised by message to info@meet-sally.com or info@meet-sally.com, as well as through the Application. We respond without delay and in any case within one (1) month of receiving the request. The period may be extended by a further two (2) months where necessary, taking into account the complexity or number of requests, with notice to you within the first month.
19. Complaint to the Supervisory Authority
You have the right to lodge a complaint with the competent supervisory authority, in accordance with Article 77 GDPR:
Hellenic Data Protection Authority, 1-3 Kifisias Ave., P.C. 115 23, Athens, telephone +30 210 6475600, email contact@dpa.gr, website www.dpa.gr.
You also retain the right to an effective judicial remedy against a decision of the supervisory authority, as well as against the controller or the processor, in accordance with Articles 78 and 79 GDPR. Finally, you retain the right to compensation in accordance with Article 82 GDPR.
20. Minors
The Service is addressed exclusively to persons who have reached 18 years of age. We do not knowingly collect data from minors. If such collection is established, the data is deleted without delay.
Specifically for the Game, your date of birth is requested before first participation. A declared age below 18 results in exclusion from the feature. Before any prize is awarded, the winner's age is verified. A prize awarded to a minor is withdrawn.
21. Cookies and Related Technologies
The use of cookies and related technologies on the website, as well as of the software tools embedded in the Application, is described in detail in the Cookie Policy, which forms an integral part of this Policy.
22. Amendments to this Policy
This Policy may be revised. In the event of a material change, we will notify you through the Application or by electronic message at least thirty (30) days before it takes effect. Each version bears a date and number. The history of versions is kept and available on request.
